Impact
Dell Command Update versions prior to 5.7.1 contain a time‑of‑check time‑of‑use race condition that can potentially allow a low‑privileged user with local access to gain elevated system privileges. This flaw is a classic race condition weakness classified as CWE‑367, and its exploitation could enable the attacker to perform actions normally restricted to higher privilege levels.
Affected Systems
All installations of Dell Command Update earlier than version 5.7.1 are affected.
Risk and Exploitability
The CVSS base score of 7.3 indicates a high severity risk. The EPSS score is less than 1 %, suggesting exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires local access from a user with limited rights, the threat is confined to compromised or otherwise accessible workstations; nevertheless, the potential for privilege escalation remains significant.
OpenCVE Enrichment